User Story: Abdelkrim Rahmania
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Recently active
Hi,I’m using fortimanager provisionning template to manager my IPSec VPN.I’m create a template.In this template I create a IPSec tunnel (Phase 1 and phase 2) with a name like myipsec_model.To create a second Ipsec tunnel, I’m click on clone option. A new tunnel it created with this name : clone_myipsec_model.I can’t rename the new IPSec configuration. I cleck on rename button change the name but this one is not change.I’m use fortimanager 7.6.7.Thanks you for your helpRegardsStéphane
Hi,For one of our customer, I have got the FortiGate 200G firewall as rented device as we are yet to receive our own new firewalls due to lead time. Meanwhile after changing the device password, firewall is asking for Forti care registration which I don't have as this been rental device, is there any way forward for this, I tried skipping the registration from bios but firewall does not boot further with error - Failed to boot the system.
I have two 5G modem with same IP ranges 192.168.0.1/24. When i change modem IP ranges, internet speed 1 out of 100 and very poor. I need solution to connect both modems to use as 50/50 weight. kindly guide me the steps. really i am fresher for network setup.
want download fortiauthenticator vm
Hi, I have a couple of related questions about FortiSIEM Windows Agent architecture:Is it possible to install the FortiSIEM Windows Agent and configure it to send event data directly to the Supervisor, without going through a Collector? Does an All-in-One Supervisor deployment have built-in Collector capabilities? In other words, can the Supervisor itself receive uploads from Windows Agents, or is a dedicated Collector node always required for Agent-based log collection? If a separate Collector is mandatory, is there any workaround for small/single-node deployments, or is a Collector required regardless of environment size?
I'm facing a strange issue with a new FortiGate VM instance running on Proxmox.EnvironmentHypervisor: Proxmox VE FortiGate: FortiGate VM Disk image: fortios.qcow2 Access: Web GUI over HTTPS Version: FortiGate-VM64-KVM v8.0.0.build0167.260420 (GA.F)IssueI created a new FortiGate VM using the fortios.qcow2 image.The VM boots successfully, and I can access the FortiGate GUI login page. I can also enter the admin credentials and authentication is successful.However, immediately after successful login, I am logged out and redirected back to the login page.So the behavior is:FortiGate GUI Login ↓Enter credentials ↓Authentication successful ↓GUI starts loading ↓Immediately logged out ↓Redirected back to Login pageThere is no normal session timeout involved because the logout happens immediately after login.Troubleshooting already attemptedI also tried increasing the administrator timeout:config system global set admintimeout 30endHowever, this did not res
Can you link your fortinet work account with your personal account so that the NSE’s transfer, kind of like microsoft’s way?Does it work all the time or does it depend on different factors, if so, what are the factors that make the process difficult or complicated?
Hello Fortinet Community,I have installed FortiGate-VM64 FortiOS 8.0.0 in my EVE-NG lab environment.The FortiGate VM boots normally, and I am able to access the GUI login page.Current IssueI can successfully enter my credentials and the GUI appears to authenticate successfully. However, immediately after login, I am logged out and redirected back to the login page.In other words:Open FortiGate GUI. Enter username and password. Authentication appears successful. GUI starts to load. Immediately after that, the session is terminated and I am returned to the login screen.EnvironmentPlatform: EVE-NG Device: FortiGate-VM64 FortiOS: 8.0.0 Build: 0167 Image: FGT_VM64_KVM-v8.0.0.F-build0167-FORTINET.out.kvm.zip Deployment: KVM/EVE-NGLicense StatusThe FortiGate license is showing Up to Date / Active, so there does not appear to be an obvious licensing issue.What I have checkedFortiGate VM is booting normally. GUI is reachable. Username/password are accepted. License status shows up to date. The
Would it be possible to get more info logged on the reason why the disposition was deferred? is ther a setting in the configuration that regulates this? Can a whitelisted sender also be “blocked” like this? Would whitelisting of the domain or sender by the user be sufficient to avoid this? Could the receiver be informed when there is a mail stuck as "Accept; Defer disposition"? With the reason why?
Hi everyone,I’m having an issue when trying to activate the trial license on a FortiGate VM running on GNS3 (KVM).When I execute the following command:execute vm-licenseand confirm with y, I get this error:Requesting FortiCare Trial license, proxy:(null) curl forticare failed, 28 Failed to request forticare license 28. Failed to download VM license.Additional system information:FortiGate-VM64-KVM # get system status Version: FortiGate-VM64-KVM v7.2.13,build1762,260128 (GA.M) License Status: Invalid VM Resources: 1 CPU/1 allowed, 1992 MB RAM/2048 MB allowedThe VM image used:FFW_VM64_KVM-v7.2.13.M-build1762-FORTINET.out.kvm.zipThis is a fresh deployment on GNS3 using KVM.
Issue: my domain xyz.com is build on next js when webiste is loaded xyz.com/_next/static urls are loaded which loads multiple js files , waf ddos policy has threshold 50 req. and multiple js files are when loaded waf suspects it as DDOS attack.... now i cant increse threshold for whole domain xyz.comwhat is the solution ?
Hello,I have two FortiGate 1800F units running FortiOS 7.4.12. One unit is licensed, while the other is currently unlicensed. I am planning to purchase the required license for the second unit, but it may take some time.For the time being, I need to configure the two units as an HA cluster before the license for the second unit is available. Is this supported? Will HA, configuration synchronization, and failover work properly during this period? Are there any risks or limitations I should be aware of?I would appreciate your advice and recommendation.Thank you.
Hi All , Am using the following network and wanted to implement Remote Access VPN over Fortinet60F using public IP available on Wifi DSL modem. What would be the preferred method to deploy Firewall Transparent or routed mode. as per my knowledge am not able to implement RA VPN using transparent mode. Right ?Secondly if am not using DHCP on DSL modem can I assigned IP from Fortinet LAN Interface DHCP service and WIFI authentication from DSL modem for connectivty purposes. Or any better idea to do it. Thanks in advance for tips and ticksregards
We are experiencing an issue with our FortiGate DHCP server where IP addresses are repeatedly marked as "Removed due to conflict."We have already performed the following checks:Verified that there are no DHCP reservations or static mappings for the affected IP addresses. Confirmed there are no duplicate static devices configured on the FortiGate. Changed the DHCP IP range to a new subnet/range.Despite these changes, the issue still occurs and clients continue to receive the "Removed due to conflict" message.Could you please advise what else we should check or how to permanently resolve this issue?Thank you.
Hi Team, could you please help clarify this for me?I just want to make sure whether FortiMail is included in the UTP bundle. If not, how can I use or activate it?Thank you and hope to hearing back from you.
Hello,I followed this technical tip:Fortinet Technical Tip – Quickly isolate hosts that have disabled or uninstalled the Persistent AgentIt works very well when I stop and restart the Persistent Agent. The host is correctly detected as At-Risk, and I can see the VLAN change from the remediation VLAN back to the production VLAN as expected.However, when I completely uninstall the Persistent Agent and then reinstall it, the host remains in "Agent Not Communicating" status. The status does not change after the agent has been reinstalled.After reinstalling the agent, I have to delete the host from FortiNAC and restart the workstation before it is detected correctly again.Is this expected behavior?I also have a question regarding the following statement from the technical tip:"An Event Mapping can be created that immediately changes the host status to 'At-Risk' as soon as an event 'Persistent Agent Not Communicating' is created."Does this Event Mapping apply to all hosts, regardless of thei
Hi everyone,Is it possible to register the FortiClient to EMS Cloud without needing the invitation code. We have more than 300 PCs to install the client and we dont want to enter the invitation to each of them. Bests,FortiEng
Hi,I would like to know if anyone else is experiencing similar issues with FortiEndpoint EMS Cloud and the integrated FortiEDR feature.Our environment is currently running:FortiClient EMS Cloud: 7.4.7 build 2194 (Mature) FortiClient: 7.4.7 Windows 11 25H2: Build 26200.8875 FortiEDR Engine assigned by EMS: 5.2.8.0044Originally, we noticed that some endpoints using the same EMS policies and profiles had FortiEDR working and connected, while others showed FortiEDR Disabled in FortiClient and Disconnected in FortiEDR Cloud.Both working and affected endpoints are operating in the same environment and network, which makes the different behavior seem questionable. We are also seeing the same issue on endpoints in customer environments, so it does not appear to be limited to a single device or network.We also tested multiple FortiClient versions, including 7.4.4, 7.4.5, and 7.4.6, but the behavior remained the same.On affected endpoints, the Collector reported:FortiEDR Detected incompatible ma
We are trying DOT1x auth via AD user .Endpoint going in dot1x process and Cisco Switch forward the request to Fortinac but the authentication process is not completing .Continuously showing “RADIUS not enabled on device”.
Hi everyone,We are running a FortiClient ZTNA Access Proxy deployment for our UAT environment and have run into a persistent connection loop immediately following the latest Fortinet ZTNA update. We are looking to see if anyone has hit this specific behavior or has a confirmed Bug ID/Workaround.🚨 The Symptoms Error Encountered: ZTNA Application Not Found (Error Code: 022) with the message Client certificate is not provided. Device Information: N/A. Behavior: It only affects users connecting from external networks (off-fabric). Internal corporate network connections work fine. The Loop: When we perform clean reinstalls or manual re-registrations, it works perfectly for exactly 2 hours, and then abruptly drops back into Error 022. 🛠️ Troubleshooting & Root Cause Analysis Done So FarWe have thoroughly mapped out the behavior and ruled out basic configuration errors: The 2-Hour Pattern & Compliance Discovered: * The 2-hour survival window strongly pointed to a periodic server
I recently bought a Fortigate 60F from Ebay. There is no firmware installed nor is there a backup firmware. How can I get a copy of a firmware to load for my lab? Or is it possible to get past this step to use for a lab?
Hello,I am experiencing a Security Fabric GUI issue on a FortiGate HA cluster after an HA failover and failback.Environment:- Root FortiGate: FortiGate 101F HA Active-Passive cluster- FortiOS: 7.4.11- Five downstream FortiGates- All FortiGates are running FortiOS 7.4.11- Security Fabric uses TCP/8013Issue timeline:1. Before the HA event, the original primary FortiGate displayed all downstream FortiGates correctly in the Security Fabric device dropdown and topology.2. The original primary FortiGate was powered off.3. The secondary FortiGate became the new primary.4. Immediately after logging in to the new primary, the Security Fabric device dropdown already displayed "No topology devices", and the topology could not be displayed correctly.5. The original primary later came back online and became primary again.6. The issue remained present after the failback.7. However, when logging in directly to any downstream FortiGate, the full Fabric Root and downstream device list is displayed corr
Hifound this https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=&ved=2ahUKEwjWmp6foZuWAxUe1wIHHSbkAusQFnoECBsQAQ&url=https%3A%2F%2Fcommunity.fortinet.com%2Ffortimanager-27%2Ftechnical-tip-how-to-validate-a-provisioning-template-via-api-call-229028&usg=AOvVaw3Jc-lv31tjbMtHsp7LpW2V&opi=89978449only i don’t have access, does this aricle still exitst?
When I attempt to Telnet into a Cisco switch located downstream of a FortiGate 50G (FG-50G), the Telnet connection fails.However, through cross-testing, I discovered an odd workaround: Whenever I modify any Firewall Policy on the FG-50G (even an irrelevant change, such as removing a service from a disabled policy), the previously failed Telnet connection to the downstream switch suddenly starts working normally.Unfortunately, if the system is left idle for a while, the Telnet connection issue returns.Network Architecture & Environment Setup Upstream & Downstream Switches: Cisco switches, connected via LACP configured to allow all VLANs. Plaintext interface Port-channel1 switchport mode trunkend FortiGate 50G: Configured in Transparent Mode. Aggregate Interface Configuration: edit "downlink" set vdom "root" set allowaccess ping https ssh snmp radius-acct set broadcast-forward enable set l2forward enable set stpforward enable set type aggregate set me
Hello guys, I would like to understand whether anyone has experienced a similar issue and, if possible, identify the root cause.I recently performed a migration from a pair of FortiGate 501E devices to a pair of FortiGate 401F devices. Both the FortiGates and FortiManager were running version 7.4.11.The firewalls being migrated were the central hub of our entire infrastructure.They were managed by FortiManager and used SD-WAN Templates extensively.In addition, they were acting as the VPN hub through VPN Manager, with approximately 100 remote FortiGate devices connected to them.To prepare for the migration, I brought the new 401F devices online and initially configured only the primary unit.At that stage, the two new firewalls were not yet configured in an HA cluster.I imported the complete configuration from the old 501E and assigned the new device to the existing SD-WAN template in FortiManager.The only step I intentionally postponed until the migration day was adding the new firewall
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.